CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,657 result(s) · page 181 of 183
CVE-2026-90539
MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows un...

CVSS 5.3 2026-09-12
CVE-2026-90538
MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attacke...

CVSS 5.3 2026-09-12
CVE-2026-90537
HIGH

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticate...

CVSS 8.2 2026-09-12
CVE-2026-90536
MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-p...

CVSS 5.3 2026-09-12
CVE-2026-90535
HIGH

Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chat...

CVSS 7.5 Flowiseai flowise 2026-09-12
CVE-2026-90534
MEDIUM

Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-l...

CVSS 6.5 Flowiseai flowise 2026-09-12
CVE-2026-90533
MEDIUM

Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization o...

CVSS 6.5 Flowiseai flowise 2026-09-12
CVE-2026-15451
HIGH

The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerabili...

CVSS 8.8 2026-09-12
CVE-2026-10148
MEDIUM

The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2....

CVSS 6.4 2026-09-12
CVE-2026-90474
MEDIUM

MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enfo...

CVSS 6.8 2026-09-12
CVE-2026-90473
MEDIUM

msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supp...

CVSS 5.3 2026-09-12
CVE-2026-90472
MEDIUM

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Att...

CVSS 5.3 2026-09-12
CVE-2026-89172
MEDIUM

Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052. This issue affects AN1044: through A; AN953: through A; S...

CVSS 5.6 2026-09-12
CVE-2026-85200
HIGH

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. T...

CVSS 7.5 2026-09-12
CVE-2026-85198
MEDIUM

The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and includi...

CVSS 6.5 2026-09-12
CVE-2026-78175
HIGH

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method...

CVSS 8.8 2026-09-12
CVE-2026-78159
CRITICAL

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insuff...

CVSS 9.8 2026-09-12
CVE-2026-78006
CRITICAL

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is d...

CVSS 9.8 2026-09-12
CVE-2026-77161
MEDIUM

The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to ins...

CVSS 6.5 2026-09-12
CVE-2026-17585
MEDIUM

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1...

CVSS 5.3 2026-09-12
1 179 180 181 182 183
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.